CyberTrustWorks — One Platform. Total Trust.

Fussion_GRC domain 6 of 15

Third-Party & Vendor Risk

Assess, tier, contract and monitor every vendor that touches your data, with evidence for regulators and auditors.

Fussion_GRC consumes data from your existing tools. It does not perform security scanning.

The problem

What problem this domain solves

Third-party risk management covers how vendors are onboarded, assessed, tiered by criticality, bound by contract clauses, and monitored for the life of the relationship.

Questionnaires sent by email and tracked in spreadsheets.
No single list of which vendors process personal or critical data.
Contracts missing security and breach-notification clauses.
Assessments done once at onboarding and never repeated.

For the CISO

Why this matters to the CISO

Many breaches start at a supplier. RBI outsourcing guidance, the DPDP Act (for data processors) and ISO 27001 supplier controls all require documented vendor due diligence and monitoring.

Critical and high-risk vendors, their issues and decisions awaiting approval.

How it works

How Fussion_GRC works in this domain

Fussion_GRC consumes data from your existing tools. It does not perform security scanning. It connects to the tools that already hold third-party risk data, then does the following:

  1. 01Tiers vendors by data access, criticality and spend.
  2. 02Sends the right questionnaire per tier and scores responses.
  3. 03Checks contracts for required clauses and flags missing ones.
  4. 04Schedules re-assessment by tier and alerts on rating changes.

Data in

Exactly where the data comes from

Source toolData receivedTypical sync
Procurement / ERP (SAP Ariba, Coupa)Vendor list, spend, contract datesDaily
Contract repositorySecurity clauses, DPA, renewal datesOn change
Vendor questionnairesResponses, attachments, certificationsOn submission
External ratings (optional)Security ratings and breach newsDaily

Typical frequencies; exact intervals depend on each tool's API limits and your configuration. Connector availability varies — see integrations.

Data flow

From your tools to the boardroom

Your existing tools
Procurement / ERP (SAP Ariba, Coupa)
Contract repository
Vendor questionnaires
External ratings (optional)
Fussion_GRC
  1. 1. Vendor
  2. 2. Assessment
  3. 3. Risk tier
  4. 4. Contract
  5. 5. Evidence
  6. 6. Monitoring
Outputs
Controls & evidence
Risk updates
Owner workflows
Executive reporting
Fussion_GRC consumes data from your existing tools. It does not perform security scanning.

Automation

Automation and workflows

Workflows created

  • Vendor → assessment → risk → contract → evidence → monitoring
  • Certification expiring → vendor reminder → updated evidence
  • High-risk vendor → treatment plan → approval

Actions for leaders

  • Approve onboarding of a high-risk vendor
  • Request missing contract clauses
  • Review vendors with a rating drop

Controls & evidence

Controls and evidence

Controls are defined once and mapped across frameworks. See supported frameworks.

Controls

  • Vendor due diligence before onboarding
  • Security clauses in contracts
  • Periodic reassessment by tier
  • Offboarding with data return or deletion

Evidence generated

  • Completed assessments
  • Signed DPAs and contract clauses
  • Certification copies with expiry
  • Offboarding confirmations

AI assistance

How Fussion AI helps

Answers come from your own Fussion_GRC data, with sources. Learn about Fussion AI.

Questions you can ask

  • "Which vendors are high risk?"
  • "Summarise this vendor's SOC 2 report exceptions."
  • "Which processors handle personal data without a DPA?"
Fussion AIIllustrative
Which vendors are high risk?
Based on the latest data from Procurement / ERP (SAP Ariba, Coupa) and Contract repository, here is what needs attention:
  • Questionnaires sent by email and tracked in spreadsheets.
  • No single list of which vendors process personal or critical data.
  • Contracts missing security and breach-notification clauses.

Every point links to its source record. Recommendation only — a named owner approves decisions.

Dashboard

Dashboard example

Roles

Who uses this domain

CISO

Many breaches start at a supplier. RBI outsourcing guidance, the DPDP Act (for data processors) and ISO 27001 supplier controls all require documented vendor due diligence and monitoring.

CIO

Sees how third-party risk affects IT services, investment priorities and the systems the business depends on.

Security Manager

Runs day-to-day third-party risk operations from one queue instead of separate tool consoles.

GRC Manager

Maps third-party risk controls to frameworks, tracks evidence freshness and prepares audits.

Control Owner

The vendors they manage, outstanding assessments and expiring documents.

Auditor

Due diligence, contract clauses and monitoring evidence for each vendor in scope.

Technical Owner

Receives specific, prioritised tasks in Jira or ServiceNow with the context needed to fix them.

Executive

Critical and high-risk vendors, their issues and decisions awaiting approval.

Integrations

Tools you can connect

  • SAP Ariba
  • Coupa
  • DocuSign
  • SharePoint
  • SecurityScorecard
  • BitSight

Named tools show typical sources; availability may be planned, roadmap or custom connector. Confirm during a demo.

See all integrations

Outcomes

Business outcomes

Critical and high-risk vendors, their issues and decisions awaiting approval.
Due diligence, contract clauses and monitoring evidence for each vendor in scope.
The vendors they manage, outstanding assessments and expiring documents.
Less manual effort: 4 processing steps and 3 workflows run automatically instead of in spreadsheets.

Example

Example workflow

  1. 1
    System

    New signal from Procurement / ERP (SAP Ariba, Coupa)

  2. 2
    Fussion_GRC

    Tiers vendors by data access, criticality and spend.

  3. 3
    Control owner

    Vendor → assessment → risk → contract → evidence → monitoring

  4. 4
    GRC manager

    Evidence attached: Completed assessments

  5. 5
    CISO

    Approve onboarding of a high-risk vendor

FAQ

Frequently asked questions

Can vendors fill questionnaires directly?

Yes. Vendors receive a secure link and only see their own questionnaire.

Do we need a paid security ratings feed?

No. External ratings are optional and can be connected if you already subscribe to one.

Does Fussion_GRC scan our environment?

Fussion_GRC consumes data from your existing tools. It does not perform security scanning.